Vulnerability index

Browse CVEs

246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Threadx HIGH 7.8
CVE-2024-2214

In Eclipse ThreadX before version 6.4.0, the _Mtxinit() function in the Xtensa port was missing an array size check causing a memory overwrite. The…

Fix: 6.4.0+
Fix from $1,950 2024-03-26
Memory Analyzer HIGH 7.1
CVE-2023-6194

In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references…

Fix: after 1.14.0
Fix from $1,950 2023-12-11
Threadx Usbx CRITICAL 9.8
CVE-2023-48697

Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause re…

Fix: 6.3.0+
Fix from $2,300 2023-12-05
Threadx Usbx CRITICAL 9.8
CVE-2023-48698

Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause re…

Fix: 6.3.0+
Fix from $2,300 2023-12-05
Threadx Usbx CRITICAL 9.8
CVE-2023-48694

Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause re…

Fix: 6.3.0+
Fix from $2,300 2023-12-05
Threadx Usbx CRITICAL 9.8
CVE-2023-48695

Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause re…

Fix: 6.3.0+
Fix from $2,300 2023-12-05
Threadx Usbx CRITICAL 9.8
CVE-2023-48696

Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause re…

Fix: 6.3.0+
Fix from $2,300 2023-12-05
Openj9 MEDIUM 5.9
CVE-2023-5676

In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentation fault if a shutdown signal …

Fix: 0.41.0+
Fix from $1,600 2023-11-15
Eclipse Ide MEDIUM 5.0
CVE-2023-4218

In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to o…

Fix: 3.13.2400 / 3.29.0+
Fix from $1,600 2023-11-09
Parsson HIGH 7.5
CVE-2023-4043

In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-…

Fix: 1.0.5 / 1.1.4+
Fix from $1,950 2023-11-03
Glassfish CRITICAL 9.8
CVE-2023-5763

In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious c…

Fix: after 6.2.5
Fix from $2,300 2023-11-03
Mosquitto HIGH 7.5
CVE-2023-5632

In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to b…

Patch available
Fix from $1,950 2023-10-18
Mosquitto HIGH 7.5
CVE-2023-3592

In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.

Fix: 2.0.16+
Fix from $1,950 2023-10-02
Mosquitto MEDIUM 5.3
CVE-2023-0809

In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets.

Fix: 2.0.16+
Fix from $1,600 2023-10-02
Remote Application Platform CRITICAL 9.8
CVE-2023-4760

In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using the FileUpload component. …

Fix: after 3.25.0
Fix from $2,300 2023-09-21
Jgit HIGH 8.8
CVE-2023-4759

Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a specially craf…

Fix: 5.13.3.202401111512-r / 6.6.0.202305301015+
Fix from $1,950 2023-09-12
Mosquitto HIGH 7.5
CVE-2023-28366

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages…

Fix: 2.0.16+
Fix from $1,950 2023-09-01
Leshan CRITICAL 9.8
CVE-2023-41034

Eclipse Leshan is a device management server and client Java implementation. In affected versions DDFFileParser` and `DefaultDDFFileValidator` (and s…

Fix: 1.5.0+
Fix from $2,300 2023-08-31
Openj9 CRITICAL 9.1
CVE-2023-2597

In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a strin…

Fix: 0.38.0+
Fix from $2,300 2023-05-22
Vert.x Stomp MEDIUM 6.5
CVE-2023-32081

Vert.x STOMP is a vert.x implementation of the STOMP specification that provides a STOMP server and client. From versions 3.1.0 until 3.9.16 and 4.0.…

Fix: 3.9.16 / 4.4.2+
Fix from $1,600 2023-05-12
Jetty MEDIUM 5.3
CVE-2023-26048

Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotated with `@MultipartConfig`) th…

Fix: 9.4.51 / 10.0.14+
Fix from $1,600 2023-04-18
Business Intelligence And Reporting Tools HIGH 8.8
CVE-2023-0100

In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host using an absolute HTTP path f…

Fix: 4.13.0+
Fix from $1,950 2023-03-15
Vert.x Web MEDIUM 5.3
CVE-2023-24815

Vert.x-Web is a set of building blocks for building web applications in the java programming language. When running vertx web applications that serve…

Fix: 4.3.8+
Fix from $1,600 2023-02-09
Glassfish HIGH 7.5
CVE-2022-2712

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting wi…

Fix: after 6.2.5
Fix from $1,950 2023-01-27
Deeplearning4j MEDIUM 5.3
CVE-2022-36022

Deeplearning4J is a suite of tools for deploying and training deep learning models using the JVM. Packages org.deeplearning4j:dl4j-examples and org.d…

Fix: 1.0.0+
Fix from $1,600 2022-11-10
Californium HIGH 8.2
CVE-2022-39368

Eclipse Californium is a Java implementation of RFC7252 - Constrained Application Protocol for IoT Cloud services. In versions prior to 3.7.0, and 2.…

Fix: 2.7.4 / 3.7.0+
Fix from $1,950 2022-11-10
Openj9 MEDIUM 6.5
CVE-2022-3676

In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlin…

Fix: 0.35.0+
Fix from $1,600 2022-10-24
Threadx Usbx CRITICAL 9.8
CVE-2022-39293

Azure RTOS USBX is a high-performance USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. The cas…

Fix: 6.1.12+
Fix from $2,300 2022-10-13
Threadx Usbx CRITICAL 9.8
CVE-2022-36063

Azure RTOS USBx is a USB host, device, and on-the-go (OTG) embedded stack, fully integrated with Azure RTOS ThreadX and available for all Azure RTOS …

Fix: 6.1.11+
Fix from $2,300 2022-10-10
Milo HIGH 7.5
CVE-2022-25897

The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory co…

Fix: 0.6.8+
Fix from $1,950 2022-09-08